CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:N/I:N/A:C
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:L
EPSS
Percentile
87.7%
The org.ovirt.engine-root is a core component of oVirt.
The following packages have been upgraded to a later upstream version: engine-db-query (1.6.2), org.ovirt.engine-root (4.4.3.8), ovirt-engine-dwh (4.4.3.1), ovirt-engine-extension-aaa-ldap (1.4.2), ovirt-engine-extension-logger-log4j (1.1.1), ovirt-engine-metrics (1.4.2.1), ovirt-engine-ui-extensions (1.2.4), ovirt-log-collector (4.4.4), ovirt-web-ui (1.6.5), rhv-log-collector-analyzer (1.0.5), rhvm-branding-rhv (4.4.6). (BZ#1866981, BZ#1879377)
Security Fix(es):
nodejs-handlebars: lookup helper fails to properly validate templates allowing for arbitrary JavaScript execution (CVE-2019-20920)
nodejs-handlebars: an endless loop while processing specially-crafted templates leads to DoS (CVE-2019-20922)
nodejs-lodash: prototype pollution in zipObjectDeep function (CVE-2020-8203)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
send --nowait to libvirt when we collect qemu stats, to consume bz#1552092 (BZ#1613514)
Block moving HE hosts into different Data Centers and make HE host moved to different cluster NonOperational after activation (BZ#1702016)
If an in-use MAC is held by a VM on a different cluster, the engine does not attempt to get the next free MAC. (BZ#1760170)
Search backend cannot find VMs which name starts with a search keyword (BZ#1797717)
[Permissions] DataCenterAdmin role defined on DC level does not allow Cluster creation (BZ#1808320)
enable-usb-autoshare is always 0 in console.vv and usb-filter option is listed two times (BZ#1811466)
NumaPinningHelper is not huge pages aware, denies migration to suitable host (BZ#1812316)
Adding quota to group doesn’t propagate to users (BZ#1822372)
Engine adding PCI-E elements on XML of i440FX SeaBIOS VM created from Q35 Template (BZ#1829691)
Live Migration Bandwidth unit is different from Engine configuration (Mbps) and VDSM (MBps) (BZ#1845397)
RHV-M shows successful operation if OVA export/import failed during “qemu-img convert” phase (BZ#1854888)
Cannot hotplug disk reports libvirtError: Requested operation is not valid: Domain already contains a disk with that address (BZ#1855305)
rhv-log-collector-analyzer --json fails with TypeError (BZ#1859314)
RHV 4.4 on AMD EPYC 7742 throws an NUMA related error on VM run (BZ#1866862)
Issue with dashboards creation when sending metrics to external Elasticsearch (BZ#1870133)
HostedEngine VM is broken after Cluster changed to UEFI (BZ#1871694)
[CNV&RHV]Notification about VM creation contain <UNKNOWN> string (BZ#1873136)
VM stuck in Migrating status after migration completed due to incorrect status reported by VDSM after restart (BZ#1877632)
Use 4.5 as compatibility level for the Default DataCenter and the Default Cluster during installation (BZ#1879280)
unable to create/add index pattern in step 5 from kcs articles#4921101 (BZ#1881634)
[CNV&RHV] Remove warning about no active storage domain for Kubevirt VMs (BZ#1883844)
Deprecate and remove ovirt-engine-api-explorer (BZ#1884146)
[CNV&RHV] Disable creating new disks for Kubevirt VM (BZ#1884634)
Require ansible-2.9.14 in ovirt-engine (BZ#1888626)
Enhancement(s):
[RFE] Virtualization support for NVDIMM - RHV (BZ#1361718)
[RFE] - enable renaming HostedEngine VM name (BZ#1657294)
[RFE] Enabling Icelake new NIs - RHV (BZ#1745024)
[RFE] Show vCPUs and allocated memory in virtual machines summary (BZ#1752751)
[RFE] RHV-M Deployment/Install Needs it’s own UUID (BZ#1825020)
[RFE] Destination Host in migrate VM dialog has to be searchable and sortable (BZ#1851865)
[RFE] Expose the “reinstallation required” flag of the hosts in the API (BZ#1856671)
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:N/I:N/A:C
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:L
EPSS
Percentile
87.7%